jcoffey-dev 200f801e2c Clear the Dependabot findings
Dependabot alerts were switched on for this repo today and reported 12 open
findings. Ten are fixed here; the other two are addressed below.

gRPC 1.83.0 -> 1.83.1, in all nine modules that require it. This is
GHSA-vp52-pcj8-j9qc / CVE-2026-84304, heap memory exhaustion via HTTP/2 DATA
frame fragmentation, affecting <= 1.83.0. It matters more than the version
delta suggests: ingest/ is a gRPC listener deliberately exposed to the internet
on :4317, so a remote OOM is reachable. mTLS narrows that to holders of a
client certificate, which is why this was not an emergency, but the fix is one
patch release away and there is no reason to carry it.

golang.org/x/oauth2 0.21.0 -> 0.27.0 in deploy/operator, an indirect
dependency (GHSA-6v2p-p543-phr9). enterprise/ was already past it at 0.36.0.

npm cookie 0.6.0 -> 0.7.2, via an overrides entry rather than a dependency
bump. @sveltejs/kit requires ^0.6.0 and still does at 2.70.3, the latest
release, so there is no version of kit that resolves this on its own -- an
override is the only route that does not involve waiting on upstream.

Three incidental changes came out of `go mod tidy` and are not mine:
genproto/googleapis/rpc moved forward as a transitive of the new grpc; pgx/v5
was reclassified from indirect to direct in enterprise/, which is simply
correct, since audit.go and cmd/enterprise-auth import it; and the proto
replace directive shuffled between require blocks at the same version.

The twelfth finding, lru (GHSA-rhfx-m35p-ff5j), is not fixed and is not
fixable here -- see the note in the pull request. It is CVSS 0, a Stacked
Borrows soundness issue in IterMut, and reaching a patched version means
tantivy 0.22 -> 0.26, which is a search engine migration rather than a
dependency bump.

Verified: all ten Go modules build, 40 test packages pass, the web app builds
and svelte-check reports 0 errors across 288 files.
2026-09-03 11:12:35 -07:00
2026-09-03 11:12:35 -07:00
2026-08-21 20:53:32 -07:00
2026-09-03 11:12:35 -07:00
2026-09-03 11:12:35 -07:00
2026-09-03 11:12:35 -07:00
2026-09-03 11:12:35 -07:00
2026-09-03 11:12:35 -07:00
2026-09-03 11:12:35 -07:00
2026-09-03 11:12:35 -07:00

Cairn OBS

Open-core, Kubernetes-native log aggregation and observability.
Built to match Splunk on capability while winning on cost-per-GB,
with honest multi-tenant RBAC and a modern language stack.

Licensed AGPLv3 in its entirety — including enterprise/. See Licensing.

What it does

Logs flow from a statically-linked Rust edge agent through Redpanda into a Go ingest pipeline, landing in ClickHouse for analytics and Tantivy for full-text search. One query language spans both stores, compiling to a single execution plan:

service=api | where status>=500 | stats count by host | sort -count
message:"connection refused" | stats count by host

Raw ClickHouse SQL stays available as an escape hatch and compiles to the same IR, so performance doesn't depend on which syntax you write.

On top of that sit dashboards, an alerting evaluator with threshold and absence rules, a CLI (cairnobsctl), a Terraform provider, and AI-assisted query authoring that runs against a self-hosted Ollama model by default — no cloud dependency.

Architecture

Component Stack
Edge agent Rust, musl static target
Transport Redpanda (Kafka API)
Ingest / parse Go
Analytical store ClickHouse
Full-text index Tantivy (Rust)
Control plane / API Go, gRPC + REST gateway
Control-plane metadata PostgreSQL
Frontend SvelteKit + TypeScript
Deployment Kubernetes Operator (kubebuilder), Helm, docker-compose

PostgreSQL is scoped strictly to control-plane config — dashboards, panels, alert rules and state, notification targets, delivery log — because those need row-level locking and transactional read-modify-write that ClickHouse's MergeTree family doesn't provide. Log data itself never touches it.

Full spec: docs/architecture.md. Read it before changing any component; the storage/query split in particular is deliberate.

Repository layout

Monorepo, one top-level directory per component, each with its own README.md, unit tests, and Dockerfile.

agent/      Rust edge agent (Linux + Windows)
transport/  Redpanda topics and schemas
ingest/     Go ingest and parse pipeline
storage/    ClickHouse schema and migrations
search/     Tantivy full-text index service
api/        Control plane, query compiler, RBAC
alerting/   Rule evaluator and notification delivery
metadata/   PostgreSQL schema and migrations
web/        SvelteKit frontend
cli/        cairnobsctl
proto/      gRPC service definitions
terraform/  Terraform provider
enterprise/ SSO, multi-tenancy, per-tenant provisioning
deploy/     Helm charts and Kubernetes operator
docs/       Architecture, design docs, per-phase runbooks
hack/       Development scripts

enterprise/ stays a separate module that core never imports from. Since the Phase 6 relicensing that boundary is architectural rather than legal — it keeps core buildable and deployable standalone, and keeps tenant resolution server-side.

Running locally

docker compose up

The web UI comes up on http://localhost:3000 and the API on :8080; alerting is on :8081 and enterprise auth on :8082. The agent connects to ingest over mTLS gRPC on :4317. search is reachable only on the compose network — it publishes no host port.

COMPOSE_PROFILES in .env selects the query-serving binary — single-tenant (default) or enterprise for the multi-tenant path. They're mutually exclusive, the same choice Helm's enterprise.enabled flag makes for a real cluster. Override per invocation:

COMPOSE_PROFILES=enterprise docker compose up

Kubernetes deployment via the Helm chart in deploy/.

Status

Built in phases; each has a runbook in docs/ recording how it was verified. Full per-phase detail is in docs/status.md.

Phase Scope Status
0 Agent → Redpanda → ingest → ClickHouse, queryable end-to-end Shipped
1 Windows Event Log + journald, SQL and full-text paths Shipped
2 Unified query language across both stores Shipped
3 Dashboards, alert rules, notification delivery Shipped
4 RBAC, tenant isolation, audit logging, per-tenant ClickHouse In progress
5 Frontend redesign and design system Shipped
6 License compliance audit and remediation Shipped
7 AI-assisted query authoring Shipped

Phase 4 is not shipped. The code is built and tested, but the environment lost Docker and database access partway through, so only the audit-logging guarantees were confirmed against a live database. The rest compiles and skips cleanly when no live database is configured, but is otherwise unverified — see the verification-status section of docs/phase-4-runbook.md.

The Windows agent code (EvtSubscribe, ETW, service registration) has never run on real Windows — no Windows toolchain existed in the build environment. ETW additionally sits behind a feature flag, since it needs elevated privileges. Details in agent/README.md.

Terraform provider coverage is partial by necessity: dashboards and panels have full CRUD, while alert rules and notification targets are create/destroy only, because alerting exposes no PUT /rules/{id} or PUT /targets/{id} to update against. Tenant and RBAC resources are disclosed future work — terraform/README.md accounts for exactly what exists.

Contributing

  • Conventional commits. Every change should be a logically complete, independently revertible unit.
  • Rust: cargo clippy --all-targets -- -D warnings must pass.
  • Go: go vet and golangci-lint, no globals for shared state.
  • Every UI action must map to a documented REST/gRPC call — no UI-only logic. The CLI and Terraform provider are first-class, not afterthoughts.
  • Prefer boring, well-understood dependencies. This is infrastructure software; operators need to trust it.

Licensing

Copyright (C) 2026 Coffey Labs.

AGPLv3, no exceptions — see LICENSE. enterprise/ was under a commercial-license stub from Phase 4 through Phase 5; Phase 6 relicensed it to match core. The full record and its business-model consequences are in docs/compliance/license-audit-report.md.

The default AI deployment uses qwen2.5-coder (Apache-2.0) via Ollama, chosen specifically to keep that license purity intact. The cloud adapter is pluggable, opt-in, and off by default.

S
Description
Imported from github.com during the 2026-09-20 standup (local dir: cairnobs)
Readme AGPL-3.0
2.1 MiB
Languages
Go 72.5%
Svelte 12.1%
Rust 8%
TypeScript 4%
Shell 1.3%
Other 2%